Local Privilege Escalation in AccountsService for Ubuntu Users
CVE-2026-61897
7.8HIGH
What is CVE-2026-61897?
A vulnerability in AccountsService allows for local privilege escalation due to insufficient privilege dropping before executing language helper scripts. This issue arises from the effective user ID and group ID changing to the target user, while the real user ID remains set to 0 (root). As a consequence, a shell launched by a helper script can inherit a real user ID of 0, enabling the possibility to regain root privileges. Users must update to the patched version to mitigate this security risk.
Affected Version(s)
accountsservice Ubuntu 14.04 LTS 22.07.5-2ubuntu1 < 22.07.5-2ubuntu1.6
accountsservice Ubuntu 14.04 LTS 23.13.9-2ubuntu6 < 23.13.9-2ubuntu6.1
accountsservice Ubuntu 14.04 LTS 23.13.9-8ubuntu5 < 23.13.9-8ubuntu5.2
